Skip to main content

Proof of competence

ISO/IEC 27001:2022 Annex A · Control 8.33

Test Information: A Practical Implementation Guide

Use representative test data without unnecessarily exposing sensitive or production information.

This control concerns appropriately selecting, protecting and managing test information.

Practical interpretation: Testing needs realism, but copying production data creates privacy, access and retention risk. Synthetic or masked data should be the default.

What should the control achieve?

  • Test-data needs and sensitivity are assessed.
  • Synthetic or masked data is preferred.
  • Production-data exceptions are authorized and protected.
  • Test information is retained and deleted deliberately.

Step-by-step implementation

1

Define test-data requirements

Identify fields, relationships, volume, edge cases and sensitivity needed.

2

Prefer synthetic data

Generate representative records without real individuals or secrets.

3

Mask sourced data

Apply validated irreversible or controlled pseudonymization.

4

Approve exceptions

Document why production data is essential, scope, safeguards and expiry.

5

Protect environments

Restrict access, logging, transfer and extraction.

6

Clean up

Track copies and delete after purpose and retention end.

What this could look like in practice

A payroll project uses synthetic employees for functional tests. A limited masked production subset is approved for performance testing in a restricted environment and automatically deleted after 30 days.

ActivityPractical implementationEvidence
DesignTeam defines realistic attributes without real identities.Data specification
GenerationSynthetic tool creates edge cases.Generation record
ExceptionPrivacy and owner approve masked subset.Approval
DeletionEnvironment cleanup removes test copy.Deletion log

Implementation evidence

  • Test-data policy
  • Requirements
  • Synthetic generation
  • Masking records
  • Exception approvals
  • Environment access
  • Copy inventory
  • Deletion evidence

Useful metrics

  • Non-production systems with production data
  • Test-data exceptions expired
  • Copies past retention
  • Masking validation failures

Common mistakes

  • Using production copies by default.
  • Masking names but not indirect identifiers.
  • Leaving test data indefinitely.
  • Sending data to developer laptops.
  • No inventory of extracts.

Questions an auditor may ask

  • Why is real data needed?
  • How is masking validated?
  • Who approves exceptions?
  • How are copies deleted?
Implementation test: Select a non-production data set and prove its source, transformation, approval, access, retention and deletion date.

Continue through Annex A

Explore the growing library of practical guides for all 93 Annex A controls.

Open the ISO 27001 Annex A Control Library

This independent educational guide paraphrases the practical intent of the control and does not replace the official ISO standards, professional advice or an organization-specific risk assessment. It is not affiliated with or endorsed by ISO.